Two malicious Python packages impersonating tools for interacting with popular AI ChatGPT and Claude were recently spotted on the Python Package Index (PyPI), the official repository of Python libraries.

These packages remained invisible for over a year, secretly undermining development environments and stealing sensitive information. According to cybersecurity researcher Leonid, the malicious packages were exploiting the popularity of AI tools in software.
See more: Compromised S3 buckets used in attacks on npm packages
Developers who wanted to integrate ChatGPT and Claude into their projects installed these packages, believing them to be legitimate sources for leveraging OpenAI and Anthropic. The names of the packages have not yet been revealed, but they mimicked legitimate libraries with seemingly normal capabilities, while secretly containing malicious scripts. These scripts stole sensitive data, such as API keys, credentials, and possibly proprietary code, and sent them to external servers controlled by the hackers.
The researcher noted that the packages had been avoiding detection for over a year, highlighting significant security challenges in open source ecosystems. PyPI, a key tool for Python, has seen increased attention in recent years due to the rise of malicious actors exploiting its openness.
This breach has raised concerns in the development community, highlighting the dangers of relying on unverified third-party libraries. Developers are urged to immediately check their dependencies and review any recent installations of AI-related packages.

Read also: Malicious PyPi packages created by Lazarus
PyPI maintainers are expected to remove the malicious packages and strengthen security protocols to prevent similar incidents in the future. Experts recommend adopting best practices, such as verifying the authenticity of packages, using virtual environments, and leveraging automated dependency scanners to detect vulnerabilities.
Source: gbhackers
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
